@techreport{acosta-crypto-agility-manifest-01, number = {draft-acosta-crypto-agility-manifest-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-acosta-crypto-agility-manifest/01/}, author = {Leon Nicolas Acosta}, title = {{A Well-Known URI and JSON Format for Publishing Cryptographic Posture (the Crypto-Agility Manifest)}}, pagetotal = 16, year = 2026, month = aug, day = 6, abstract = {This document defines a discoverable, machine-readable JSON document, the crypto-agility manifest, that a website or source repository publishes at the well-known URI "/.well-known/crypto-agility.json" to declare its cryptographic posture: a readiness summary, a compact Cryptography Bill of Materials (CBOM) summary, an optional link to a posture attestation, the migration policy it measures itself against, and an optional self-declared conformance statement with justified exceptions. The manifest lets an automated consumer, such as an AI coding agent, a continuous-integration bot, or an auditor's tool, discover a project's crypto posture the way it already discovers a security contact from "security.txt". The manifest is a public, self-reported claim; it is not a proof. It is intended to complement, not replace, a full CBOM inventory, serving as the CBOM's public-facing discovery counterpart. This document is a proposal. It is not an IETF product and is not a standard of any kind.}, }